This guide describes the setup of the Microsoft Network Policy Server for use with eduroam in the UK. Whilst it is the key component, the Organisational RADIUS Server (ORPS) is just one element of your eduroam deployment and this guide must be read in conjunction with:
i) Implementing eduroam Roadmap https://community.ja.net/library/janet-services-documentation/implementing-eduroam-roadmap
and
This document is intended for Technical managers wishing to explore the topic of safeguarding minors and vulnerable adults on eduroam, particularly in respect of users roaming away from the home campus to locations where the eduroam service provides unfiltered access to the internet. The background to the issue is considered together with an appraisal of how the key elements of eduroam support the safeguarding of users and how eduroam deployment may be tailored to suit the policy in force at the individual organisation.
Aiming to serve as a business decision making tool, this document provides guidance on the costs involved in implementing eduroam. The costs are broken down into clearly defined work areas and categorised by type of service - Visited-only, Home, Home and Visited.
eduroam technical specification checklist (based on specification 1.4)
A precis of all requirements and recommendations that can be checked during deployment of eduroam at a site - or when reviewing your service or checking issues.
Please note that proxying of RADIUS accounting datagrams to the NRPS is now deprecated - and will be forbidden in the next iteration of the technical specification
This guide describes the setup of Operator-Name on Cisco ISE for use with eduroam in the UK. Whilst it is the useful component, the Opertor-Name attribute is just one element of your eduroam deployment and this guide must be read in conjunction with:
You must be logged in to be able to view this file!
Provides searchable list of all sites in the UK providing eduroam services and details the Wi-Fi ciphers required together with service provision information: number of APs, NAT, application proxy, IPv6, wired eduroam, operator-name injection.
TL;DR - TLS 1.2 negotiation in forthcoming OS releases require sites running RADIATOR, FreeRADIUS 2 and FreeRADIUS 3 to upgrade, NPS sites may need reconfiguring.
Overview
TLDR; most client issues are solved by ensuring that the client is configured via a deployment tool
IOS9
Apple have changed the behaviour of IOS 9 with enterprise WiFi. It appears that if your organisation is using a certificate not natively known by the device then it will no longer accept just username/password entry and present you with a 'verify the server' option. it just silently quits.
Author - Dr Alan Buxey 27/2/2012
Author - Dr Alan Buxey 27/2/2012
This document looks at how a RADIUS packet is handled within the FreeRADIUS server. This fundamental knowledge will help us to understand where and how we configure the server, where we can adjust or optimise the flow and where to start looking if things go wrong. A good starting reference point is the native configuration after installation; reassuringly, by default this should just work!
